Back to skill

Security audit

AI 企业画像

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward AI-company research helper that uses a disclosed third-party API token and query script, with privacy and credential-care caveats but no hidden or destructive behavior.

Install only if you are comfortable sending AI-company research queries and filters to the Jiqizhixin service. Keep JQZX_API_TOKEN out of chat, logs, screenshots, shell history, and repositories, and avoid using confidential client or non-public strategy terms in queries unless your organization has approved that provider.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Low
Confidence
90% confidence
Finding
The skill instructs users to export `JQZX_API_TOKEN` as an environment variable but does not warn against printing, logging, committing, or echoing the token during troubleshooting or script execution. In a shell-enabled skill context, missing credential-handling guidance increases the chance of accidental exposure through command history, logs, screenshots, or downstream tools.

Missing User Warnings

Low
Confidence
93% confidence
Finding
The API usage section directs queries to an external service and encourages sending company names, investor filters, tags, and research parameters, but it does not disclose that user-provided research inputs may be transmitted off-platform. In an enterprise-research context, those inputs can themselves be sensitive business intelligence, making silent exfiltration to a third-party API a meaningful privacy and confidentiality risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.